COMPANY
Trust Centre
The Trust Centre publishes what a security or procurement review works through, rather than emailing it case by case. A review runs along four lines: evidence about the PCI DSS Level 1 processing environment, validated annually; the data flow, since hosted checkout and Rapid.js keep full card numbers out of merchant systems and that decides everything else; the supply chain, meaning the subprocessor categories, the published register naming each provider and the data processing terms; and the response path, a published vulnerability disclosure programme with a security contact.
- Evidence about the processing environment
- Data flow before anything else
- Subprocessors and where data sits
- Data processing terms
Try it, edit values and click buttons
API request
POST /v1/payments
{
"amount": 24900,
"currency": "CAD",
"capture": true,
"metadata": { "order_id": "4821" }
}Response
Click "Send request" to see the API response
Processing payment…
201 Created
{ "id": "pay_7xK2m", "status": "approved", "amount": 24900 }Demonstration data only
In detail
Evidence about the processing environment
PCI DSS Level 1 validation covers the systems that touch cardholder data and is renewed annually. A reviewer should be reading evidence about that environment, not a marketing claim about it.
Data flow before anything else
Hosted checkout and Rapid.js keep full card numbers out of merchant systems. Establish that first, because it decides the scope of every other question in the review.
Subprocessors and where data sits
The subprocessors page sets out the categories that support the infrastructure, what each is engaged to do and what it can reach; section 9 of that page publishes the register naming the individual providers, and sets out the route for obtaining the current full list. It is the question most vendor questionnaires ask twice in different words.
Data processing terms
The data processing addendum is the processing terms in writing, and it divides the work activity by activity: what RapidCents does on a merchant’s instruction as its processor, and what it does on its own account as a controller. It is written to the privacy legislation that binds RapidCents rather than to the GDPR, so it offers no standard contractual clauses. The privacy policy covers how personal information is collected, used and protected for merchants and site visitors.
Vulnerability disclosure
A published responsible disclosure programme and a security contact, so a researcher or a customer’s security team has a route that does not depend on finding the right inbox.
Accessibility and commercial terms
Reviews routinely cover accessibility conformance on public surfaces and the terms governing the merchant relationship. Both are published rather than produced on request.
Related pages
Security & compliance
More on how RapidCents handles this.
ExplorePCI compliance
Which self-assessment questionnaire your integration puts you on.
ExploreSubprocessors
The categories that support the infrastructure, what each can reach, the published register, and how to obtain the current full list.
ExploreData processing addendum
The processing terms in writing, applying to every merchant without a separate signature.
ExploreVulnerability disclosure
Responsible disclosure programme and security contact.
ExploreAccessibility
Conformance target for public marketing surfaces.
Explore
Questions about Trust Centre
What will you provide for our vendor questionnaire?
Evidence about the processing environment in the form of the Attestation of Compliance for the PCI DSS Level 1 validation, the security statement describing the controls in force, the subprocessor register naming each provider with what it is engaged to do, together with the current full list, the data processing addendum, the privacy policy, the accessibility statement and the vulnerability disclosure route. Most of that is published, so a reviewer can start reading before anyone is on a call.
Where does the platform run, and what happens to backups?
On redundant virtual environments across cloud data centres, whose providers operate backup power generation and dual-path power distribution, run continuous on-site surveillance and restrict physical access to key personnel through multi-factor controls including biometrics. Databases are backed up daily, both between data centres and offsite. The subprocessors page sets out the infrastructure and hosting category and what it can reach, and section 9 of that page publishes the register naming the providers it evidences, states in terms that the cloud data centre providers behind the platform are not among them, and sets out the route for obtaining the current full list.
What monitoring and network controls are in place?
Intrusion detection and intrusion prevention run at the firewall and locally on every server, screening traffic for suspicious behaviour, abnormal volumes and malicious code, with the prevention layer acting rather than only recording. Server firewalls default to deny-all, so a connection is refused unless a reviewed rule permits it. Servers are hardened and patched, major vulnerabilities are addressed without delay under change control, and there is no wireless access to the platform environment.
What governs personal information, and how long is it kept?
The privacy policy covers collection, use and protection under PIPEDA, and the data processing addendum is the processing terms in writing, which clause 19 of that addendum records as applying to every merchant and binding RapidCents without a separate signature. A designated Privacy Officer is accountable for compliance with the policy and for answering requests and complaints, reachable at the North York address or on +1 (844) 957-2743. Cardholder data is retained for up to 24 months of inactivity; identity and onboarding records are held for the period anti-money-laundering legislation requires.
Do you meet an accessibility standard?
Public marketing surfaces target WCAG 2.2 AA conformance, and the accessibility statement is published with the rest of the legal set. A document in an alternate format, or feedback about a barrier, can be requested through the contact page, by telephone on +1 (844) 957-2743, by mail, or in person at the North York address. Feedback can be left anonymously, though a reply needs a way to reach you.
Take the next step
Talk to a RapidCents specialist
RapidCents Fee Check reads a processing statement and shows interchange separately from the markup. Upload a statement for an instant breakdown, or open a merchant account and start accepting payments on one account.
- No obligation
- Canadian payment specialists
- Secure statement upload





